webPromedium

Lab 59 — NetPulse — RCE via Command Injection in Network Diagnostics

hackadvisor

Task: NetPulse monitoring platform with Network Diagnostics module that passes user-supplied interface name directly to shell command without sanitization. Solution: OS command injection via semicolon in iface parameter of /api/diagnostics/interface endpoint to execute arbitrary commands as root and read /root/flag.txt.

$ ls tags/ techniques/
api_parameter_tamperinghoneypot_flag_detectionos_command_injection_via_semicolonshell_metacharacter_injectionunsanitized_shell_exec

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups